Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Vim — Vulnerabilities & Security Advisories 74

All 74 CVE vulnerabilities found in Vim, with AI-generated Chinese analysis, references, and POCs.

This page details security weaknesses affecting the vim text editor, a widely used cross-platform command-line text editor. It aggregates known vulnerabilities related to this specific software, focusing on the Common Weakness Enumeration (CWE) classifications associated with its codebase and release history. The collection encompasses a broad spectrum of security flaws, including buffer overflows, use-after-free errors, integer overflows, and injection vulnerabilities that may allow remote code execution or denial of service. The data covers historical records from the earliest tracked incidents up to the most recent disclosures, providing a comprehensive timeline of security issues. Readers can utilize this resource to track vendor advisories and patches issued for vim over time. It also serves as a reference for understanding the prevalence and nature of specific weakness classes within the application’s development lifecycle. Furthermore, users can look up the product’s vulnerability history to assess risk trends and prioritize mitigation efforts. This aggregation aims to support security analysts, developers, and system administrators in identifying and addressing potential exposure points. By centralizing this information, the page facilitates a clearer view of the security posture of vim, enabling informed decisions regarding updates and configuration hardening. The content is organized to help users navigate from high-level vulnerability types to specific implementation details without requiring prior deep knowledge of the underlying code structure.

Vendor: unspecified

CVE IDTitleCVSSSeverityPublished
CVE-2026-73078 Vim: Arbitrary Code Execution via Netrw Menu Construction CWE-77 8.6 High2026-08-11
CVE-2026-73077 Vim: Arbitrary Code Execution via Shell Keyword Lookup CWE-78 8.4 High2026-08-11
CVE-2026-73076 Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim` CWE-94 8.4 High2026-08-11
CVE-2026-73075 Vim: Out-of-bounds Access in Popup Opacity Handling CWE-124 4.6 Medium2026-08-11
CVE-2026-73074 Vim: Heap Buffer Overflow in Text Property Handling CWE-190 7.1 High2026-08-11
CVE-2026-73072 Vim: Heap Buffer Overflow when Loading a Spell File CWE-122 8.5 High2026-08-11
CVE-2026-73071 Vim: Use-after-free in JSON Decoding CWE-416 3.3 Low2026-08-11
CVE-2026-73070 Vim: Stack Buffer Overflow in the Vim Socket Server CWE-121 6.8 Medium2026-08-11
CVE-2026-59856 Vim: Arbitrary Code Execution via PHP Omni-Completion CWE-94--2026-07-09
CVE-2026-59858 Vim: Arbitrary Code Execution via C Omni-Completion CWE-94--2026-07-09
CVE-2026-59857 Vim: Out-of-bounds Write in SAL Soundfolding CWE-787--2026-07-09
CVE-2026-55693 Vim: Out-of-bounds Write in Spell File Word Count CWE-787--2026-06-25
CVE-2026-55892 Vim: Out-of-bounds Write in Spell File Prefix Dump CWE-787 5.5 Medium2026-06-25
CVE-2026-55895 Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename CWE-78--2026-06-25
CVE-2026-57451 Vim: Out-of-bounds Read in Text Property Count CWE-125 5.3 Medium2026-06-25
CVE-2026-57452 Vim: Out-of-bounds Read with libsodium-encrypted Files CWE-125 5.5 Medium2026-06-25
CVE-2026-57453 Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction CWE-77 6.5 Medium2026-06-25
CVE-2026-57454 Vim: Out-of-bounds Read with Text Properties CWE-125--2026-06-25
CVE-2026-57455 Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument CWE-787--2026-06-25
CVE-2026-57456 Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings CWE-94--2026-06-25
CVE-2026-52860 Vim: Arbitrary Code Execution via Python Omni-Completion CWE-94--2026-06-11
CVE-2026-52859 Vim: Out-of-bounds Read in Terminal Screen Snapshot CWE-125--2026-06-11
CVE-2026-52858 Vim: Arbitrary Code Execution via Python Omni-Completion CWE-94--2026-06-11
CVE-2026-47162 Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name CWE-74 7.3 High2026-06-11
CVE-2026-47167 Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex CWE-94--2026-06-11
CVE-2026-46483 Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag CWE-78 3.6 Low2026-05-15
CVE-2026-45130 Vim: Heap Buffer Overflow in spell file loading CWE-122 6.6 Medium2026-05-08
CVE-2026-44656 Vim: OS Command Injection via 'path' completion CWE-78 7.8AIHighAI2026-05-08
CVE-2026-42307 Vim: OS Command Injection in netrw CWE-78 4.4 Medium2026-05-08
CVE-2026-41411 Vim: Command injection via backtick expansion in tag filenames CWE-78 6.6 Medium2026-04-24

All 74 known CVE vulnerabilities affecting Vim with full Chinese analysis, references, and POCs where available.